KHRAT
- First seen
- 2018-06-20 00:00:00
- Malware type
- rat, keylogger, screen-capture, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 12:48:17
Targeted industries: government-and-public-sector
Targeted regions: country_code:kh
Context
According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address. KHRAT provides the threat actors typical RAT features and access to the victim system, including keylogging, screenshot capabilities, remote shell access and so on.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Khrat_Auto (yara-rule)
Reports & references
- forcepoint.com — Trojanized Adobe Installer Used Install Dragonok S New Custom Backdoor (report)
- Palo Alto Unit 42 — Rancortaurus (report)
- Palo Alto Unit 42 — Rancor Cyber Espionage Group Uses New Custom Malware To Attack Southeast Asia (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Khrat (report)
- researchcenter.paloaltonetworks.com — Unit42 Updated Khrat Malware Used In Cambodia Attacks (report)